Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted third argument to the rrdtool.graph function, aka ZEN-15415, a related issue to CVE-2013-2131.
{
"binaries": [
{
"binary_name": "liblua5.2-rrd-dev",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "liblua5.2-rrd0",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrd-dev",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrd-ruby",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrd-ruby1.9.1",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrd4",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrdp-perl",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "librrds-perl",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "python-rrdtool",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "rrdcached",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "rrdtool",
"binary_version": "1.4.7-2ubuntu5"
},
{
"binary_name": "rrdtool-tcl",
"binary_version": "1.4.7-2ubuntu5"
}
]
}